healthcare and healthtech

HIPAA for healthcare and healthtech

HIPAA governs the protection of health information in the United States. For software touching protected health information (PHI), the Security Rule and Breach Notification Rule are where most of the engineering work lands.

Start free HIPAA overview

Why it matters for healthcare and healthtech

If you build for providers, payers, or patients and handle PHI, HIPAA applies, often as a business associate to a covered entity. Partners will ask you to sign a Business Associate Agreement and to evidence your safeguards.

What to focus on

Administrative, physical, and technical safeguards

The Security Rule organizes requirements into administrative, physical, and technical safeguards. In practice that means risk analysis, access controls, audit controls, encryption where appropriate, and workforce training.

Know your role: covered entity or business associate

Most healthtech vendors are business associates. That means a Business Associate Agreement (BAA) with each covered entity you serve, plus the safeguards and breach obligations HIPAA requires of associates.

HIPAA pairs well with SOC 2

Healthtech buyers frequently want both a HIPAA posture and a SOC 2 report. The underlying controls (access, encryption, monitoring, incident response) overlap heavily, so the work compounds.

Do it once, not twice

Keel is built on one crosswalked control library, so a control you implement for HIPAA counts toward every other framework it satisfies. Add a second framework later and it mostly reuses this work. See the crosswalk explorer for the exact overlap.

Start free Check your readiness

Common questions

Do healthtech companies need SOC 2 as well as HIPAA?

Very often yes. HIPAA is a legal obligation for PHI; SOC 2 is the assurance report buyers request. They share many controls, so on Keel you collect the evidence once and it serves both.

Is there a HIPAA certification?

No. HIPAA has no official certification; you demonstrate compliance through your safeguards, risk analysis, policies, and evidence. Keel helps you organize and maintain exactly that.

Do I store PHI in Keel?

No. Keel is where you run your HIPAA compliance program - safeguards, risk analysis, policies, and evidence that your controls operate - not a system of record for protected health information. Keep PHI out of Keel and it stays outside your BAA scope; because Keel does not process or store your PHI, it is not acting as your business associate.

Framework names are referenced factually for guidance. Keel is not affiliated with or endorsed by the bodies that publish them. See our legal and trademarks page.